#RSAC
Dr. Edward G. Amoroso
Toward Distributed and Virtualized
Enterprise Security
STR-T11
CEO TAG Cyber
Stevens Institute of Technology, M&T Bank,
Applied Physics Lab/JHU, New York University
@hashtag_cyber
eamoroso@tag-cyber.com
#RSAC
Recent Public Enterprise Hacks
#RSAC
How Many Darts to Fill the Bucket?
#RSAC
How Many Darts to Fill the Bucket?
#RSAC
Which Method Protects the Cookies Better?
#RSAC
Enterprise Perimeter – Theory
#RSAC
Disallow External
Access
#RSAC
Internal
Asset
Internal
Asset
Allow Internal
Access
Disallow External
Access
#RSAC
Email
Product
Marketin
g
HR
Records
Sales
Corporat
e
CFO
Outsourc
e
IT
Systems
Dev/Ops
Info/Data
Trusted Internal
Enterprise Access
Trusted Internal
Lateral Traversal
Disallow External
Access
#RSAC
Email
Product
Marketin
g
HR
Records
Sales
Corporat
e
CFO
Outsourc
e
IT
Systems
Dev/Ops
Info/Data
Partner Access
Gateway
Web
Gateway
Remote Access
Gateway
Outsource Access
Gateway
Email
Gateway
Unknown
Gateway
Unknown
Gateway
Unknown
Gateway
#RSAC
Email
Marketin
g
Web
Gateway
Mistake 1: Email accepted from anyone with
no regard for controls such as DMARCEmail
Gateway
Records
Mistake 2: Someone from Marketing
clicks on a Phish
Mistake 3: Easy lateral
traversal across the
enterprise LAN.Mistake 4: Web egress
allowed to uncategorized
Internet site
Advanced Persistent Threat (APT)
#RSAC
Enterprise Perimeter – Actual
#RSAC
Internal
Asset B
Internal
Asset D
Internal
Asset C
Internal
Asset A
#RSAC
Internal
Asset A
Internal
Asset D
Internal
Asset B
Internal
Asset C
#RSAC
Internal
Asset A
Internal
Asset D
Outsourcin
g
Internal
Asset B
Outsourcing Access
Gateway
#RSAC
Internal
Asset A
Internal
Asset D
Internal
Asset B
Outsourcing Access
Gateway
Outsourcin
g
Cloud/vDC
#RSAC
Internal
Asset A
Internal
Asset D
Internal
Asset B
Outsourcin
g
Virtual
Micro-Segment
Policy Enforcement
Cloud/vDC
#RSAC
Internal
Asset A
Email
Internal
Asset B
Email
Gateway
Outsourcin
g
Cloud/vDC
#RSAC
Internal
Asset A
Internal
Asset B
Email
Gateway
Outsourcin
g
Cloud/vDC
Email
Cloud/vDC
#RSAC
Internal
Asset A
Internal
Asset B
Outsourcin
g
Email
Cloud/vDC
Cloud/vDC
#RSAC
Partner
Internal
Asset B
Outsourcin
g
Email
Cloud/vDC
Cloud/vDC
Partner
Gateway
#RSAC
Partner
Internal
Asset B
Outsourcin
g
Email
Cloud/vDC
Cloud/vDC
Cloud/vDC
Partner
Gateway
#RSAC
Partner
Internal
Asset B
Outsourcin
g
Email
Cloud/vDC
Cloud/vDC
Cloud/vDC
#RSAC
Partner
Internal
Asset B
Outsourcin
g
Email
Cloud/vDC
Cloud/vDC
Cloud/vDC
Legacy
Enterprise
#RSAC
Partner
Outsourcin
g
Email
Internal
Asset B
#RSAC
Partner
Outsourcin
g
Email
Internal
Asset B
Cloud/vDC
Policy
#RSAC
Partner
Outsourcin
g
Email
Internal
Asset B
Policy
#RSAC
Asset A
Asset C
Asset D
Asset B
C&C
#RSAC
Asset A
Asset C
Asset D
Asset B
C&C
#RSAC
Node
Node
Node
Node
C&C
#RSAC
C&C/Node
Node
Node
Node
C&C
#RSAC
Node
Node
Node
Node
C&C
#RSAC
Node
Node
Node
Node
C&C
#RSAC
Node
Node
Node
Node
C&C
#RSAC
#RSAC
Distributed Micro-Segmented Enterprise Architecture
Logical
Interaction
Logical
Interaction
Isolated
Micro-Segments
#RSAC
Warning: Global Perimeters are Not Secure
Enterprise
LAN
Enterprise
LAN
Attack Surface
Perimeter
Attack Surface
Attack Surface
#RSAC
Isolating a Server from a Perimeter Makes it More Secure
Enterprise
LAN
Enterprise
LAN
Attack Surface
Perimeter
Attack Surface
Attack SurfaceIsolated Server
#RSAC
Global Department of State Network
#RSAC
Global Department of State Perimeter is Not Secure
#RSAC
Bureaucratic
Clinton Email Server
Global Department of State Perimeter is Not Secure
#RSAC
Isolating the Clinton Email Server Made it More Secure
Isolated Clinton
Email Server
#RSAC
Applying Enterprise Cyber Security to Politics
#RSAC
https://www.tag-cyber.com/
@hashtag_cyber
Apply What You’ve Learned: Download the PDFs

Toward distributed and virtualized enterprise security